Skip to content

Check your download

Make sure the file is complete and really comes from VelaOS before you write it to a USB stick.

Two checks, a few minutes in total. The signature proves that the list of checksums was made by VelaOS. The checksum proves that your file matches that list, byte for byte. If either check fails, don't use the file: delete it and download it again.

What you need

  • From Downloads (log in first): the image file, for example velaos-26.10-amd64.raw.zst, plus SHA256SUMS and SHA256SUMS.sig.
  • The VelaOS public key, velaos.pub. It is printed below and on the Downloads page.
  • Put all four files in the same folder, and open a terminal in that folder.

The VelaOS public key

This key is public, so it is safe to share. Save it as velaos.pub. It is the same key every VelaOS device uses to check its updates.

1. Check the signature

  1. 1

    Install cosign

    cosign is a free signing tool from the open-source Sigstore project. Get it from the cosign install page:

    • macOS: brew install cosign
    • Linux: your distribution's package (dnf install cosign, apt install cosign) or the release binary
    • Windows: download cosign-windows-amd64.exe from the cosign releases page and rename it to cosign.exe
  2. 2

    Check the checksum list against the VelaOS key

    The same command works in Terminal (macOS, Linux) and PowerShell (Windows):

    cosign verify-blob --key velaos.pub --signature SHA256SUMS.sig --insecure-ignore-tlog=true SHA256SUMS

    It must end with Verified OK. Anything else means the list was changed or isn't from VelaOS: stop here.

    Why --insecure-ignore-tlog=true?

    cosign warns that it skips the public Sigstore log. VelaOS releases are private, so they are not written to that public log. Your proof is the VelaOS key above, which is checked in full.

2. Check the SHA-256 checksum

Pick your computer. Each way ends with a clear yes or no.

Windows: PowerShell

  1. 1

    Compare the file with SHA256SUMS

    Open PowerShell in the download folder and paste:

    $file = Get-Item .\velaos-*.raw.zst
    $expected = (Select-String -Path .\SHA256SUMS -Pattern $file.Name -SimpleMatch).Line.Split(' ')[0]
    $actual = (Get-FileHash $file -Algorithm SHA256).Hash.ToLower()
    if ($actual -eq $expected) { "OK: the checksum matches" } else { "STOP: the checksum does not match" }

    A large file takes up to a minute. You want OK: the checksum matches.

Windows: Command Prompt

  1. 1

    Print the checksum

    certutil -hashfile velaos-26.10-amd64.raw.zst SHA256
  2. 2

    Compare it by eye

    Compare the 64 characters it prints with the line for your file in SHA256SUMS, or with the SHA-256 on the Downloads page (use its copy button). Upper or lower case doesn't matter; every character must match.

macOS: Terminal

  1. 1

    Check the file against SHA256SUMS

    shasum -a 256 -c SHA256SUMS 2>/dev/null | grep velaos

    You want velaos-26.10-amd64.raw.zst: OK. FAILED means the file is damaged or changed.

Linux: terminal

  1. 1

    Check the file against SHA256SUMS

    sha256sum --ignore-missing -c SHA256SUMS

    You want velaos-26.10-amd64.raw.zst: OK. FAILED means the file is damaged or changed.

Both checks passed?

The file is complete and comes from VelaOS. Next: write it to a USB stick and install.

If a check fails

  • Download the file again from Downloads. A broken connection is the usual cause.
  • Make sure SHA256SUMS, SHA256SUMS.sig and the image come from the same release (same version number).
  • Still failing? Don't install it. Tell us at velaos.ch/security: a file that fails its signature check can mean someone tampered with it.
Was this helpful?
Updated 2026-10-10